UPSC Prelims Practice Questions — A civilisational approach to social media

Q1. When Australia's social media minimum age law came into force in December 2025, how many platforms stood designated as age-restricted for under-16s, counting the livestreaming service added shortly before commencement?

  • A. Seven
  • B. Nine
  • C. Ten
  • D. Thirteen

Q2. Consider the following statements comparing the United Kingdom's announced social media restriction for minors with Australia's law: 1. Australia's restriction is already in force, whereas the United Kingdom's is intended to take effect only from early 2027. 2. Both measures bring private messaging services such as WhatsApp within the scope of the restriction. 3. Both measures adopt the same age threshold, applying to children below sixteen years. Which of the statements given above is/are correct?

  1. Australia's restriction is already in force, whereas the United Kingdom's is intended to take effect only from early 2027.
  2. Both measures bring private messaging services such as WhatsApp within the scope of the restriction.
  3. Both measures adopt the same age threshold, applying to children below sixteen years.
  • A. 1 only
  • B. 1 and 2 only
  • C. 1 and 3 only
  • D. 2 and 3 only

Q3. Which one of the following correctly describes the standing of the United Kingdom's announced under-16 social media restriction relative to comparable measures elsewhere?

  • A. It would be the world's first such restriction, since no country has so far brought an under-16 social media ban into force anywhere.
  • B. It would be the first such restriction in Europe, every other European country having ruled out age-based limits on social media entirely.
  • C. It would extend to all online services accessible in the United Kingdom, including private messaging applications, with no exceptions.
  • D. It would follow Australia, which was the first country to bring an under-16 social media ban into force, in December 2025.

Q4. Under India's data protection framework, what precisely does the obligation cast on a Data Fiduciary in relation to a child's personal data require?

  • A. That the child's own assent be recorded through a one-time password sent to a mobile number verified as belonging to the household.
  • B. That the school or other educational institution in which the child is enrolled record the permission on the child's behalf.
  • C. That the consent of the parent or lawful guardian be obtained, with due diligence to confirm that the person consenting is an identifiable adult.
  • D. That the consent obtained be routed through and countersigned by a Consent Manager registered with the Data Protection Board.

Q5. Consider the following statements regarding the Digital Personal Data Protection Act, 2023 and the Rules made under it: 1. The Rules were notified more than two years after the Act was enacted, and their notification marked the full operationalisation of the Act. 2. The Rules provide for a phased compliance timeline of eighteen months for organisations to transition to the new obligations. 3. Unlike the parent Act, the Rules newly permit a child's personal data to be processed without guardian consent for purposes such as healthcare and education. Which of the statements given above is/are correct?

  1. The Rules were notified more than two years after the Act was enacted, and their notification marked the full operationalisation of the Act.
  2. The Rules provide for a phased compliance timeline of eighteen months for organisations to transition to the new obligations.
  3. Unlike the parent Act, the Rules newly permit a child's personal data to be processed without guardian consent for purposes such as healthcare and education.
  • A. 1 and 2 only
  • B. 2 and 3 only
  • C. 1 and 3 only
  • D. 1, 2 and 3

Q6. Part III of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which prescribes the Code of Ethics for publishers of news and current affairs content and of online curated content, is administered by which one of the following?

  • A. The Ministry of Electronics and Information Technology, which notified the Rules under the Information Technology Act, 2000
  • B. The Ministry of Home Affairs, acting through the National Crime Records Bureau and the cybercrime coordination centre
  • C. The Ministry of Women and Child Development, in view of the child-protection objectives of the content classification system
  • D. The Ministry of Information and Broadcasting, which also formulates the oversight mechanism at the third tier

Q7. Consider the following obligations under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021: 1. Appointment of a Chief Compliance Officer resident in India, responsible for ensuring compliance with the Act and the Rules. 2. Enabling identification of the first originator of information on the platform, in specified circumstances. 3. Acknowledgement of a user complaint within twenty-four hours of its receipt. 4. Appointment of a nodal contact person for coordination with law enforcement agencies. Which of the above are correctly identified as additional due diligence applicable specifically to a significant social media intermediary?

  1. Appointment of a Chief Compliance Officer resident in India, responsible for ensuring compliance with the Act and the Rules.
  2. Enabling identification of the first originator of information on the platform, in specified circumstances.
  3. Acknowledgement of a user complaint within twenty-four hours of its receipt.
  4. Appointment of a nodal contact person for coordination with law enforcement agencies.
  • A. 1, 2 and 3
  • B. 1, 2 and 4
  • C. 2, 3 and 4
  • D. 1, 3 and 4

Q8. Consider the following statements about the evolution of India's statutory framework for digital and intermediary regulation: 1. The Information Technology Act, 2000 has remained unamended since its enactment, every subsequent change having been effected exclusively through subordinate rules. 2. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 replaced the intermediary guidelines rules framed in 2011. 3. The Digital Personal Data Protection Act, 2023 came to be fully operationalised only upon the notification of the Rules made under it in November 2025. 4. Section 79 of the Information Technology Act confers on intermediaries an absolute immunity from liability for third-party content, irrespective of their compliance with prescribed due diligence. Which of the statements given above is/are NOT correct?

  1. The Information Technology Act, 2000 has remained unamended since its enactment, every subsequent change having been effected exclusively through subordinate rules.
  2. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 replaced the intermediary guidelines rules framed in 2011.
  3. The Digital Personal Data Protection Act, 2023 came to be fully operationalised only upon the notification of the Rules made under it in November 2025.
  4. Section 79 of the Information Technology Act confers on intermediaries an absolute immunity from liability for third-party content, irrespective of their compliance with prescribed due diligence.
  • A. 2 and 3
  • B. 1 and 4
  • C. 1 and 3
  • D. 3 and 4

Q9. Following the amendment of India's intermediary regulation framework to create an appellate tier above intermediaries' internal grievance officers, how many Grievance Appellate Committees were notified by the Government?

  • A. Two
  • B. Three
  • C. Four
  • D. Five

Q10. Consider the following: 1. Issue of notices to intermediaries including X, YouTube and Telegram requiring prompt and permanent removal of Child Sexual Abuse Material, coupled with a warning of withdrawal of safe harbour under Section 79 of the Information Technology Act. 2. A memorandum of understanding between the National Crime Records Bureau and the National Center for Missing and Exploited Children, United States, enabling sharing of tipline reports on online child sexual exploitation. 3. Mandatory self-classification of online curated content by publishers into five age-based categories, with parental locks for content classified U/A 13+ and above. 4. A statutory bar on all persons below sixteen years of age from holding accounts on any social media platform in India. Which of the above are correctly identified as measures forming part of the Government of India's online child-safety architecture?

  1. Issue of notices to intermediaries including X, YouTube and Telegram requiring prompt and permanent removal of Child Sexual Abuse Material, coupled with a warning of withdrawal of safe harbour under Section 79 of the Information Technology Act.
  2. A memorandum of understanding between the National Crime Records Bureau and the National Center for Missing and Exploited Children, United States, enabling sharing of tipline reports on online child sexual exploitation.
  3. Mandatory self-classification of online curated content by publishers into five age-based categories, with parental locks for content classified U/A 13+ and above.
  4. A statutory bar on all persons below sixteen years of age from holding accounts on any social media platform in India.
  • A. 1 and 4 only
  • B. 2 and 4 only
  • C. 1, 2 and 4 only
  • D. 1, 2 and 3 only